Your data is your data.
We treat consumer credit information the way a bank does — encrypted, audited, never sold, never shared with lenders. Here's exactly what that means.
What we encrypt and how.
Encryption-at-rest and encryption-in-transit are table stakes. We go further on the AI side — bureau data is redacted before it reaches any model.
AES-256-GCM at rest
Every credit report, every analysis, every consent record sits in the database as ciphertext. The key is rotated every 90 days. A database leak gets a leaker bytes, not a credit profile.
TLS 1.3 in transit
All traffic between your browser, our servers, and Equifax flows over TLS 1.3 with modern cipher suites. No data ever moves in the clear.
Privacy-redacted AI prompts
When the funding-readiness analysis runs, your full SSN, DOB, full name, and full address are stripped before any model sees the prompt. Score, utilization, account-age aggregates are sufficient — and that's all the model gets.
The list of things you'd be surprised aren't on our servers.
Most fintech security pages list what they protect. Here's the inverse — what isn't on our servers in the first place.
- Plaintext SSN — only the last 4 are stored, encrypted, and only at the moment of bureau enrollment
- Plaintext credit reports in logs — every log line is filtered through a PII scrubber before write
- Bureau passwords or auth credentials — we use Equifax's hosted IDV; your credentials never touch our servers
- Your data in any AI prompt without redaction — name, full address, SSN, DOB are stripped pre-prompt
- Card data — your card number is tokenized at the payment processor and never touches our servers; we never see or store the full card number
What FCRA-compliant means for us.
The Fair Credit Reporting Act is the federal law that governs how consumer credit data can be obtained, used, and disclosed. We are a regulated subscriber.
What we do with your data — and what we don't.
Spot something? Let us know.
Found a security concern, a vulnerability, or a privacy question we haven't answered? Email security and we'll respond within one business day.
security@advisorhub.ai